Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.

Description:WMI could not indicate changes to log consumer. Windows Management Instrumentation (WMI) could not publish the changes for the event <event class> generated by <event source> to the logging consumer. These events from this source will not be logged. Status is <status> : <status message>.

Comments:Kent Twyman
As per Microsoft: "WMI could not notify the Application Center Log consumer of changes for the specified event and event source. Effect: Logging for this specific event from the specific event source to the Application Center log will not be available on this computer. A subset of events will still be written to the Windows Event Log. This failure does not affect event logging on other cluster members, but the events for this computer will not be available to the cluster controller until this situation is fixed." See the link to ME288621.